Cloud Evidence Tracing System: An integrated forensics investigation system for large-scale public cloud platform

被引:3
|
作者
Wu, Songyang [1 ]
Sun, Wenqi [1 ]
Ding, Zhiguo [1 ]
Liu, Shanjun [1 ]
机构
[1] Minist Publ Secur, Third Res Inst, Shanghai, Peoples R China
来源
FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION | 2022年 / 41卷
关键词
Integrated forensics; Large-scale cloud; Virtual machine; FRAMEWORK; TOOLS;
D O I
10.1016/j.fsidi.2022.301391
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the rise of cloud computing, many systems are migrating to public cloud platforms. Numerous crimes are committed in the cloud, including the establishment of illegal websites and the storage of illegal data. Using virtualization technology, data can be logically stored in the same virtual host, but also physically distributed across multiple hard drives, clusters, or even countries. In these circumstances, using the traditional forensic method of physical preservation will consume a great deal of resources, which will clog the forensic process. In order to develop an effective cloud investigation solution, two challenges must be overcome. First, the difficulty of collecting data consistently when the VMs (Virtual Machines) involved are deployed across multiple CSPs. Second, the difficulty of keeping track of all the files created during the forensic workflow. We developed CETS (Cloud Evidence Tracing System), which utilizes CSP's existing API to perform a variety of forensic operations including acquisition, preservation, and emulation, as well as data analysis and file management. To evaluate the system, we created three cloud environments in the laboratory, including a forensic target cloud, a preservation cloud, and an emulation cloud, and conducted a series of forensic experiments. CETS was shown to significantly increase the investigator's investigative efficiency and reduce the investigation workflow's resource consumption. Currently, CETS has collected data exceeding 2 PB, rerun more than 2000 virtual hosts, including servers and databases, supported more than 300 investigation cases related to cloud platforms. CETS can be an example system for efficient forensic investigation in large-scale cloud environment.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Infiniviz: Taking Quake 3 Arena on a Large-Scale Display System to the Next Level
    Bundulis, Rudolfs
    Arnicans, Guntis
    PROCEEDINGS OF THE 2018 23RD CONFERENCE OF OPEN INNOVATIONS ASSOCIATION (FRUCT), 2018, : 91 - 98
  • [42] PIoT: A Performance IoT Simulation System for a Large-Scale City-Wide Assessment
    Firouzabadi, Abbas Dehghani
    Mellah, Hakim
    Manzanilla-Salazar, Orestes
    Khalvandi, Reza
    Therrien, Vincent
    Boutin, Victor
    Sanso, Brunilde
    IEEE ACCESS, 2023, 11 : 56273 - 56286
  • [43] Towards Modeling Large-Scale Data Flows in a Multidatacenter Computing System With Petri Net
    Song, Weijing
    Wang, Lizhe
    Ranjan, Rajiv
    Kolodziej, Joanna
    Chen, Dan
    IEEE SYSTEMS JOURNAL, 2015, 9 (02): : 416 - 426
  • [44] Implementation of multi agents based system for process supervision in large-scale chemical plants
    Natarajan, Sathish
    Srinivasan, Rajagopalan
    COMPUTERS & CHEMICAL ENGINEERING, 2014, 60 : 182 - 196
  • [45] Onboard disease prediction and rehabilitation monitoring on secure edge-cloud integrated privacy preserving healthcare system
    Jayaram, Ramaprabha
    Prabakaran, S.
    EGYPTIAN INFORMATICS JOURNAL, 2021, 22 (04) : 401 - 410
  • [46] TwoFish-Integrated Blockchain for Secure and Optimized Healthcare Data Processing in IoT-Edge-Cloud System
    Karuppusamy, Geetha Sarojini
    Kumar, Manoj S.
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2025, 36 (03):
  • [47] Large-scale hybrid test of a curved bridge considering complete boundary condition by a large spatial loading system
    Tian, Yingpeng
    Chen, Jie
    Du, Chunbo
    Xu, Dan
    Zhou, Huimeng
    Sun, Zhiguo
    Li, Quanwang
    Wang, Dongsheng
    Wang, Tao
    EARTHQUAKE ENGINEERING & STRUCTURAL DYNAMICS, 2024, 53 (06): : 2032 - 2054
  • [48] A novel deep learning based intrusion detection system for the IoT-Cloud platform with blockchain and data encryption mechanisms
    Ponniah, Krishna Kumar
    Retnaswamy, Bharathi
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2023, 45 (06) : 11707 - 11724
  • [49] Asymptotic optimality of a greedy randomized algorithm in a large-scale service system with general packing constraints
    Stolyar, Alexander L.
    Zhong, Yuan
    QUEUEING SYSTEMS, 2015, 79 (02) : 117 - 143
  • [50] Large-scale health system transformation in the United Kingdom Implementing the new care models in the NHS
    Maniatopoulos, Gregory
    Hunter, David J.
    Erskine, Jonathan
    Hudson, Bob
    JOURNAL OF HEALTH ORGANIZATION AND MANAGEMENT, 2020, 34 (03) : 325 - 344